CVE-2011-0226

High PUBLISHED

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and...

Apple · iOS

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High

At a Glance

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.

ios
CVE Published
Jul 19, 2011
Exploitation Reported
Jul 19, 2011
CVSS
9.3 High
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • APPLE-SA-2011-07-15-1 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2011//Jul/msg00000....
  • openSUSE-SU-2011:0852 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00015...
  • APPLE-SA-2011-07-15-2 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2011//Jul/msg00001....
  • APPLE-SA-2011-10-12-3 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003....
  • RHSA-2011:1085 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1085.html
Show 15 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.